Privacy Policy

Green Britain Group Privacy Policy

Last updated: March 2023

This privacy policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed, shared and used by us, and how you can exercise your privacy rights. Please read the following carefully to understand how we look after your personal data.

Who we are

This policy applies to personal information collected by Green Britain Group Limited (registered no. 12456925). In these terms and conditions “Green Britain Group”, “we”, “our” or “us” means Green Britain Group Limited, and “you” or “your” means you, our customer.

Green Britain Group is registered with the ICO with registration number ZB521368

The Green Britain Group is made up of different legal entities. For information about the Green Britain Group, please see the homepage of our Website.

How we collect your Personal Data and why

“Personal Data” means any information about a living individual from which that person can be identified. It does not include data which has been anonymised.

We may collect, use, store and transfer different kinds of Personal Data about you, as follows:

Identity Data • first name • last name • username or similar identifier • title • gender

Contact Data • email address • telephone numbers • billing address • delivery address

Financial Data • bank account and payment card details

Transaction Data • details about payments to and from you • other details of products and services you have purchased from us

Technical Data • your internet protocol (IP) address • your login data, browser type and version • time zone setting and location • browser plug-in types and versions • operating system and platform

Profile Data • your username and password • purchases or orders made by you • your interests, preferences, feedback and survey responses.

Usage Data • information about how you use our website, products and services.

Marketing and Communications Data • your preferences in receiving marketing from us and our third parties • your communication preferences.

The Personal Data that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your Personal Data.

We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect aggregated data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this privacy policy.

We do not collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

This website is not intended for children, and we do not knowingly collect data relating to children.

Information that you provide directly • We collect your Identity, Contact, Financial and Transaction Data when you contact us, register with us to receive updates, use any of our services or order any goods from us, use our website under the domain name www.greenbritaingroup.com (the “Website”) or request information or assistance from us. • Where we need to collect Personal Data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

Information that we collect automatically • When you use the Website, we collect Technical Data about your activity by using cookies and similar tracking technologies. • Cookies are small amounts of information which we store on your computer. Cookies make it easier for you to log on to and use the Website during future visits. They also allow us to monitor Website traffic and to personalise the content of the Website for you. You may set up your computer to reject cookies by modifying the settings in your browser although, in that case, you may not be able to use certain features on our Website. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log onto our Website. Collecting this information enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors.

How to manage your cookies

You may set up your computer to reject cookies by modifying the settings in your browser however, you may not be able to use certain features on our Website. If you don’t adjust your browser settings to refuse cookies, our system will issue cookies when you log onto our Website.

Collecting information from cookies enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them.

We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors. For further information about cookies and how to disable them please go to aboutcookies.org.

We use the following Cookies: Cookie: _fbp Placed by: Facebook Description: Used by Facebook to store and track visits across websites for marketing/tracking purposes. This cookie is essential / non-essential.

Cookie: _ga Placed by: Google Description: Set by Google Analytics and used to distinguish users for marketing and or tracking purposes. Cookie: _gat_{unique-ID} Placed by: Google Description: A cookie placed by Google which is used for functional purposes, specifically throttle request rate. Cookie: _gcl_au Placed by: Google Description: This cookie is placed by Google Adsense and used to store and track conversions for marketing / tracking purposes. Cookie: _gid Placed by: Google Description: Google Analytics set this cookie and it is used to distinguish users. _hjAbsoluteSessionInProgress Hotjar Hojar set this cookie and it is used to detect the first pageview session of a user setting a true/false value. Cookie: _hjFirstSeen Placed by: Hotjar Description: Hojar set this cookie, and it’s used to identify a new users first session. Again, it stores a true/false value which indicates whether this was the first time Hotjar saw this user. It is used by recording filters which identify new user sessions. Cookie: _hjid Placed by: Hotjar Description: Again, Hotjar set this cookie and it is used when a user first lands on a page with the Hotjar script. It is used to persist the Hotjar User ID, unique to that site on the browser. This ensures that behaviour in subsequent visits to the same site will be attributed to the same user ID. Cookie: _hjTLDTest Placed by: Hotjar Description: This is used when the Hotjar script executes and attempts to determine the most generic cookie path, instead of the page hostname. This is done so that cookies can be shared across subdomains (where applicable). To determine this, we attempt to store the _hjTLDTest cookie for different URL substring alternatives until it fails. After this check, the cookie is removed. Cookie: _uetvid Placed by: Bing Description: Bing Ads set this cookie and it’s used to store and track visits across websites for marketing/tracking purposes. Cookie: 1P_JAR Placed by: Google Description: Google use this cookie to set up a unique ID to remember your preferences for marketing/tracking purposes. Cookie: CONSENT Placed by: Google Description: Google set this cookie, like the cookie above, it is used to remember your preferences for marketing/tracking purposes. Cookie: DV Placed by: Google Description: Cookie set by Google and used to save the users interests and preferences for personalised marketing/tracking purposes. Cookie: NID Placed by: Google Description: Google use this cookie and use it by setting a unique ID to remember your preferences for marketing/tracking purposes. Cookie: VISITOR_INFO1_LIVE Placed by: YouTube Description: Youtube set this cookie and it’s used to estimate bandwidth for functional purposes Cookie: YSC Placed by: YouTube Description: Youtube set this cookie to store a unique ID for statistical purposes. Cookie: _pk_uid (Third party persistent) Placed by: TV Squared Description: Cookie which allows the TV Squared collector to identify individual users, in order to establish lag between response activities, and to confirm continuity of campaigns being responded to. Cookie: _pk_id.{variable id} or _tq_id.{variable id} (First party persistent) Placed by: TV Squared Description: Aids reporting of site visits and actions for analytical reporting to TV Squared. Cookie: pk_ses (First party session) Placed by: TV Squared Description: Used to confirm an individual user in relation to an individual session, i.e. how long the user is on the website.

Use of your Personal Data

We will only use your Personal Data when the law allows us to. Most commonly, we will use your Personal Data in the following circumstances:

• to supply information about us or our goods or services to you; • to give you access to all parts of the Website; • to manage our contract and our relationship with you, including by verifying your identity, administering services, contacting you where necessary concerning your interest in goods or services and the Website, and handling any complaints or queries you may have; • to invoice you, take card payments, manage any disputes over the money you owe us, recover any money that you may owe us and to identify and prevent fraud or money laundering activities; • for our legitimate interests, including to administer, support, improve and develop our business and our services or goods; • to contact you for your views on our services or goods; • to notify you occasionally about important changes or developments to our services or the Website; • to administer competitions or prize draws that you may enter; • to tell you about new products or services supplied by us or third parties that we think may be of interest to you. If you would rather not receive marketing e-mails from us, please let us know by emailing us at dataprotectionofficer@ecotricity.co.uk.

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason, and that reason is compatible with the original purpose.

If we need to use your Personal Data for an unrelated purpose, we will notify you and will explain the legal basis which allows us to do so. Please note that we may process your Personal Data without your knowledge or consent, in compliance with this policy, where this is required or permitted by law.

Disclosure of your information

• Your Personal Data will be held on our systems and may be accessed by or transferred to any entity in our corporate group, including any entity that acquires us or that we may acquire. This may include staff working outside the UK and third parties, some of whom are located outside the UK. Such third parties process information, fulfil orders and provide support services on our behalf a list of third parties relevant to your account can be made available on request. • We may transfer your Personal Data as a part of a corporate reorganisation, business sale, or other merger activity, but in those circumstances any recipient will be obliged by law to comply with this policy. • We may also transfer or disclose your Personal Data to group companies, service providers, professional advisers and to such other parties as we consider reasonably necessary for the administration of any services, the Website, any related, ancillary matters (including competitions and prize draws) and related business. • We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes, and only permit them to process your Personal Data for specified purposes and in accordance with our instructions. • Countries outside the UK do not always have strong data protection laws which afford adequate protection to individuals’ Personal Data, and so we limit when we transfer data to them. When data is transferred internationally, we will always take steps to ensure it is afforded an adequate degree of protection by ensuring that at least one of the following safeguards is implemented. o We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data. o We may use specific contracts approved for use in the UK, which give Personal Data the same protection it has in the UK. • Sometimes we are required or compelled to disclose your information. We will respond to requests (in each case, limiting disclosure to the extent required) where: o our compliance is required by law; o we receive a request from a public authority or law enforcement agency, o there is a threat to the safety of you or any other person; or o we suspect you of committing a criminal offence, including fraud. • We will only otherwise disclose any of the information you provide to us when permitted to do so by applicable law or with your consent.

Legal basis for processing Personal Data

• Our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it. • We will normally collect and process personal Personal Data where we have your consent to do so, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. • In some cases, we may also have a legal obligation to collect Personal Data from you or may otherwise need the Personal Data to protect your vital interests or those of another person (for example, if we are asked to provide your telephone number or location data to the emergency services in an emergency situation). • If we ask you to provide Personal Data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Data is mandatory or not (as well as of the possible consequences if you do not provide your Personal Data). • Similarly, if we collect and use your Personal Data in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are. • The legal bases on which we process your Personal Data are summarised below:

Contract • Providing you with goods or services • Administering competitions and prize draws

Legitimate interests • Verifying your identity when you make enquiries by phone, email or letter • Marketing of our products and services (You have the right to object). • Contacting you in relation to a quotation in respect of goods or services we provide • Commencing legal or recovery proceedings against you to recover unpaid charges, where this is necessary • assisting with statistical analysis to assess and improve our services and systems • recording calls made to us for staff training and improvements to our processes and services • administering competitions and prize draws, including providing the surname and county of winners to those who enquire, or in order to comply with the requirements of the CAP Code.

Legal obligation • Responding to requests by law enforcement authorities for access to your Personal Data • Protecting our businesses and other customers from criminal or fraudulent activities • Enforcing a judgment of a court of law • The detection and prevention of theft, fraud, and money laundering offences

Consent • Marketing the services of our other group companies • Using your details in publicity where you are a competition or prize draw winner.

If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Data, please contact our Data Protection Officer at dataprotectionofficer@ecotricity.co.uk.

Security

• We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality. • We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. • Where we have given you (or where you have chosen) a password which enables you to access certain parts of our Website, you are responsible for keeping this password confidential, and for letting us know if you think that your password has been compromised. • Although Ecotricity will do its best to protect your Personal Data, it cannot guarantee the security of any Personal Data that you disclose online. You must accept the inherent security implications of using the Internet and we will not be responsible for any breach of security unless we have been be in breach of applicable laws and then only to the limits set out in the terms and conditions for the Website. • Our Website may, from time to time, contain links to and from the websites of our partner networks, advertisers, affiliates and members of our corporate group. If you follow a link to any of these websites, please note that they will have their own privacy policies/web site terms of use and we do not accept any responsibility or liability for these policies. Please check such policies before you submit any Personal Data to them.

Data Retention

• We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you. • To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. • By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.

Your legal rights

• You are entitled to access, correct or update your Personal Data. You can do so at any time by contacting us using the contact details provided under the “Contact” heading below. • In certain circumstances you can object to our processing of your Personal Data, request deletion of your Personal Data, ask us to restrict processing of your Personal Data or request portability of your Personal Data. Again, you can exercise these rights by contacting us using the contact details provided under the “Contact” heading below. • You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us using the contact details provided under the “Contact” heading below. • If we have collected and process your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on other lawful grounds. • We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. • We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Complaints

• You have the right to complain about our collection and use of your Personal Data. In the first instance you should contact our Data Protection Officer by emailing dataprotectionofficer@ecotricity.co.uk • In the event that you are unhappy with the Data Protection Officer’s response you may raise your concerns with the Information Commissioner’s Office at https://ico.org.uk/concerns/ • We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. Changes to our privacy policy • Any changes to our privacy policy in the future will be posted to the Website. When we update our privacy policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material privacy policy changes if and where this is required by applicable data protection laws. • You can see when this privacy policy was last updated by checking the “last updated” date displayed at the top of this privacy policy.

Contact

All comments, queries and requests relating to our use of your information are welcomed, using the following details:

The Data Protection Officer Ecotricity Group Limited Lion House Rowcroft Stroud GL5 3BY

Customer Services Hotline Within the UK: 0333 800 5500 Outside the UK: +44 3338 005 500

Email dataprotectionofficer@ecotricity.co.uk

For EEA based Nationals, please contact our European Representative. Details are as follows:

Company Name: Instant EU GDPR Representative Ltd Company Number: 665191 Contact Name: Adam Brogden Contact Email: contact@gdprlocal.com Contact Tel: +353 (0) 15549700

EU Dublin Address:

INSTANT EU GDPR REPRESENTATIVE LIMITED Office 2 12A LOWER MAIN STREET LUCAN CO. DUBLIN K78 X5P8 IRELAND